TLS
HTTPS for small business: how to enable it in 15 minutes.
Published 2026-04-19 · Last updated 2026-04-19 · Vantyris editorial
If your site loads on http:// rather than https://, every modern browser shows your visitors a 'Not secure' warning before they see your content. Chrome blocks form submissions on HTTP. Your conversion rate and your search ranking both suffer. Worse, any data your visitors send (login credentials, contact form details) crosses the public internet in plain text. HTTPS is no longer optional. And getting it costs nothing.
What this means for your business
- Browsers stopped tolerating HTTP-only sites years ago. Chrome and Firefox show 'Not secure' in the address bar. Safari warns on any form. Visitors read that as 'this business is sketchy' and leave.
- Without HTTPS, anything posted to your site (contact form, login page, checkout) travels unencrypted. Anyone on the same Wi-Fi network as your visitor can intercept it.
- Google has used HTTPS as a ranking signal since 2014. An HTTP-only site sits below equivalent HTTPS competitors in search results.
- Let's Encrypt issues free certificates, and every modern web host can deploy them with one toggle. There is no cost barrier to HTTPS in 2026.
How to fix
Enable a Let's Encrypt certificate at your web host or Cloudflare, then set up the HTTP-to-HTTPS redirect so old links keep working.
- Check whether your host offers Let's Encrypt. Most modern hosts (Hostinger, SiteGround, WP Engine, Cloudways, Fly, Render, Vercel) include Let's Encrypt as a one-click toggle. Log in to your hosting control panel, find the SSL section, and look for
Let's EncryptorFree SSL. - Turn it on. Click the toggle. Most hosts take 1-5 minutes to issue the certificate, and you'll see a confirmation when it's active.
- Set the HTTP-to-HTTPS redirect. You have HTTPS now, but visitors typing
http://yourdomain.comwill still hit the unencrypted version. Most hosts have a 'Force HTTPS' or 'HTTPS Redirect' toggle next to the SSL setting. Turn it on. - Test it. Open an incognito browser and visit
http://yourdomain.com(withhttp://typed out). It should redirect tohttps://yourdomain.com. Check the padlock icon in the address bar. - (Optional) Add HSTS. Once HTTPS has worked for a week or two, add a
Strict-Transport-Securityheader. It tells browsers never to load your site over HTTP again, even when a visitor typeshttp://. Most hosts let you add headers in their config. If yours doesn't, a CDN can (Cloudflare's free tier does).
Owner: Your web host's support team. · Time: 15 minutes if your host supports Let's Encrypt natively.
Common gotchas
- After enabling HTTPS, check that everything the page loads (images, scripts, stylesheets) also comes over HTTPS. A page that mixes HTTPS and HTTP resources triggers a 'mixed content' warning. Most modern hosts handle this for you. Older sites with hard-coded
http://URLs in the CMS need a database search-and-replace. - If your site sits behind Cloudflare, set SSL mode to 'Full (strict)', not 'Flexible'. Flexible decrypts at Cloudflare and serves HTTP to your origin, which is half-secure.
- Don't forget the redirect. Without it you have two parallel copies of your site, one on HTTP and one on HTTPS, which confuses search engines and visitors alike.
How to verify the fix
Run a Vantyris teaser scan to confirm HTTPS is configured and the redirect is in place. For a detailed grade, paste your domain into ssllabs.com/ssltest.
Cyber Essentials alignment
This finding informs the following Cyber Essentials control areas (the UK government's baseline scheme, a sound checklist in any country):
- A2. Secure configuration: devices and services hardened against the weaknesses they ship with by default.
Vantyris is not a CE certifying body. The mapping above is informational.
Common follow-up questions
Do I need to pay for a 'real' certificate from a CA?
No. Let's Encrypt certificates are accepted by every modern browser and are technically equivalent to paid ones. Paid certs only add brand recognition (DigiCert, Sectigo) or extended validation (the green bar, which most browsers have removed).
Will enabling HTTPS slow my site down?
No, the opposite. HTTPS enables HTTP/2 and HTTP/3, which are faster than HTTP/1.1. Sites are measurably quicker after enabling HTTPS.
What if my certificate expires?
Let's Encrypt certs expire every 90 days and renew automatically through your host. If auto-renewal breaks, your host emails you. Set a calendar reminder if you want belt-and-braces.
References
- Let's Encrypt: getting started Vendor
- NCSC: TLS for external-facing services NCSC
- MDN: Strict-Transport-Security MDN
Related explainers
- HSTS: the security header that locks HTTPS on for good.
- TLS 1.0 and 1.1: turn them off. Here's why and how.
Want Vantyris to check your domain for this and 196 other problems?
The teaser scan is free and needs no card. A verified scan starts at $10€10£10A$15¥1,500AED 40 and comes with the workspace: finding workflow, score trend, three PDF layouts, share links and monitoring.
Written by Vantyris